CVE-2025-12444
BaseFortify
Publication date: 2025-11-10
Last updated on: 2025-11-13
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | to 142.0.7444.59 (exc) | |
| apple | macos | * |
| linux | linux_kernel | * |
| microsoft | windows | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an incorrect security user interface (UI) issue in the Fullscreen UI of Google Chrome versions prior to 142.0.7444.59. It allows a remote attacker to perform UI spoofing by convincing a user to perform specific UI gestures on a crafted HTML page, potentially misleading the user about what they are interacting with.
How can this vulnerability impact me? :
The vulnerability can impact you by enabling a remote attacker to spoof the browser's UI, potentially tricking you into believing you are interacting with legitimate content or controls when you are not. This could lead to phishing or other social engineering attacks, although the severity is considered low.